
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23902 is an Incorrect Authorization vulnerability in Apache DolphinScheduler that allows authenticated users with system login permissions to use tenants not defined on the platform during workflow execution. It affects all versions of Apache DolphinScheduler prior to 3.4.1 (Maven package org.apache.dolphinscheduler:dolphinscheduler-api). The vulnerability was disclosed on April 24, 2026, with the fix available in version 3.4.1. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, OSS-Security).
The vulnerability is classified as CWE-863 (Incorrect Authorization), meaning the platform fails to correctly validate whether a tenant specified during workflow execution is actually defined and permitted within the system. An authenticated attacker with standard system login credentials can craft workflow execution requests referencing arbitrary or undefined tenant identifiers, bypassing the intended authorization boundary. No user interaction is required, and the attack is conducted over the network with low complexity. The vulnerability was reported by researcher Jihang Yu (OSS-Security, GitHub Advisory).
Successful exploitation allows authenticated attackers to execute workflows under tenant contexts that are not sanctioned by the platform, potentially gaining unauthorized access to tenant-specific resources, data, and configurations. This can result in high confidentiality and integrity impacts — including unauthorized data access and manipulation across multiple tenant environments — though availability is not directly affected. In multi-tenant deployments, this could enable cross-tenant data exposure and privilege escalation within the workflow execution context (GitHub Advisory, OSS-Security).
dolphinscheduler-api module) that accepts a tenant parameter as part of the workflow run configuration.Users should upgrade Apache DolphinScheduler to version 3.4.1 or later, which contains the fix for this vulnerability (GitHub Advisory, OSS-Security). For organizations unable to patch immediately, implementing network-level access controls to restrict who can reach the DolphinScheduler API and monitoring for workflow execution attempts involving undefined tenants are recommended interim measures. Limiting system login permissions to only trusted users can also reduce the attack surface.
The vulnerability was announced via the Apache OSS-Security mailing list and the Apache announcement list on April 24, 2026, by DolphinScheduler maintainer Wenjun Ruan (OSS-Security, Apache Announce). Social media activity was limited, with brief mentions on Bluesky and Mastodon from security-focused accounts. No significant researcher commentary or major media coverage has been identified beyond standard vulnerability aggregator listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."